Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34r8-4w7f-49v8

больше 4 лет назад

XnView 2.03 has a stack-based buffer overflow vulnerability

EPSS: Низкий
github логотип

GHSA-34r7-v6pv-xq6v

около 1 месяца назад

Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r7-q49f-h37c

почти 9 лет назад

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34r6-xm35-5vcx

около 4 лет назад

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r6-q8c8-23mx

около 1 года назад

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34r6-9vgg-pmh3

больше 2 лет назад

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r5-q4jw-r36m

3 месяца назад

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

EPSS: Низкий
github логотип

GHSA-34r5-hj3h-jf22

больше 4 лет назад

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-34r5-6j7w-235f

4 месяца назад

Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode

EPSS: Низкий
github логотип

GHSA-34r5-4vr6-q5h6

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CONST_* style argument, as the verifier cannot consider imprecise scalars to be equivalent for the purposes of states_equal check when such arguments refine the return value (in this case, set mem_size for PTR_TO_MEM). The resultant mem_size for the R0 is derived from the constant value, and if the verifier incorrectly prunes states considering them equivalent where such arguments exist (by seeing that both registers have reg->precise as false in regsafe), we can end up with invalid programs passing the verifier which can do access beyond what should have been the correct mem_size in that explored state. To show a concrete example of the problem: 0000000000000000 <prog>: 0: r2 = *(u32 *)(r1 + 80) 1: r1 = *(u32 *)(r1 + 76) 2: r3 = r1 3: r...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34r4-qfpx-74fg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-34r4-p9qh-fh37

около 4 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

EPSS: Низкий
github логотип

GHSA-34r4-h4c9-vmrj

больше 4 лет назад

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34r4-9973-43mq

больше 3 лет назад

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34r3-v64f-c8m6

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

EPSS: Низкий
github логотип

GHSA-34r3-h75p-74mh

11 месяцев назад

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r2-vc72-3cjg

около 4 лет назад

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34r2-r86v-qfp3

около 4 лет назад

bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34qx-mf6r-5f7m

больше 2 лет назад

GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current process. Was ZDI-CAN-22094.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-34qx-mf2g-mjc4

больше 4 лет назад

The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34r8-4w7f-49v8

XnView 2.03 has a stack-based buffer overflow vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34r7-v6pv-xq6v

Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-34r7-q49f-h37c

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
github логотип
GHSA-34r6-xm35-5vcx

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-34r6-q8c8-23mx

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-34r6-9vgg-pmh3

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34r5-q4jw-r36m

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

0%
Низкий
3 месяца назад
github логотип
GHSA-34r5-hj3h-jf22

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34r5-6j7w-235f

Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode

1%
Низкий
4 месяца назад
github логотип
GHSA-34r5-4vr6-q5h6

In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CONST_* style argument, as the verifier cannot consider imprecise scalars to be equivalent for the purposes of states_equal check when such arguments refine the return value (in this case, set mem_size for PTR_TO_MEM). The resultant mem_size for the R0 is derived from the constant value, and if the verifier incorrectly prunes states considering them equivalent where such arguments exist (by seeing that both registers have reg->precise as false in regsafe), we can end up with invalid programs passing the verifier which can do access beyond what should have been the correct mem_size in that explored state. To show a concrete example of the problem: 0000000000000000 <prog>: 0: r2 = *(u32 *)(r1 + 80) 1: r1 = *(u32 *)(r1 + 76) 2: r3 = r1 3: r...

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-34r4-qfpx-74fg

Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34r4-p9qh-fh37

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

2%
Низкий
около 4 лет назад
github логотип
GHSA-34r4-h4c9-vmrj

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34r4-9973-43mq

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-34r3-v64f-c8m6

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34r3-h75p-74mh

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-34r2-vc72-3cjg

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-34r2-r86v-qfp3

bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-34qx-mf6r-5f7m

GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current process. Was ZDI-CAN-22094.

CVSS3: 7.8
61%
Средний
больше 2 лет назад
github логотип
GHSA-34qx-mf2g-mjc4

The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу